CVE-2025-20757: Input Validation
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01673751; Issue ID: MSV-4644.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch MOLY01673751 - Compensating control
Mitigate remote DoS by preventing UEs from connecting to rogue base stations (e.g., restrict/monitor network access and validate connectivity/acceptable base stations as applicable in your deployment).
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20757?
CVE-2025-20757 has been classified as a serious vulnerability due to its potential to cause a remote denial of service.
How do I fix CVE-2025-20757?
To mitigate CVE-2025-20757, users should apply the appropriate security patch provided by MediaTek.
What system does CVE-2025-20757 affect?
CVE-2025-20757 affects certain MediaTek modem devices, particularly those vulnerable to improper input validation.
Is user interaction required to exploit CVE-2025-20757?
No, CVE-2025-20757 can be exploited without any user interaction.
What could be the impact of CVE-2025-20757?
The potential impact of CVE-2025-20757 includes a system crash and remote denial of service if connected to a rogue base station.